
FUCK-CDN is an automated OSINT skill for Claude Code that chains 40+ prioritized techniques to locate a CDN-protected origin IP, built for authorized assessments and defensive research.
| Tool | 0xShe/FUCK-CDN — a Claude Code skill that automates CDN origin-IP discovery with 40+ prioritized OSINT methods and cross-validation |
| Category | OSINT / reconnaissance automation for LLM coding agents |
| Primary Use | Mapping the true origin IP behind Cloudflare, EdgeOne, CloudFront, Akamai and other CDNs during authorized pentest scoping and asset inventory |
| Safe Use | For authorized security assessments, security education, CTF competitions, and defensive teams validating their own CDN/WAF exposure; the README's disclaimer requires explicit authorization from the target owner |
| Telemetry Note | Activity is largely passive (DNS, certificate logs, space-search engines) but active stages — port scans on 24 common ports, /24 neighbor scanning, sensitive-path probing — are visible to CDN/WAF logs and will trigger origin-protection alerts on monitored infrastructure |
FUCK-CDN is an interesting artifact less for what it computes than for how it is packaged: it is not a standalone binary or Python framework, but a skill file — .claude/skills/fuck-cdn.md — designed to be loaded into Claude Code, Anthropic's terminal-based coding agent. The premise is that CDN origin discovery is fundamentally a workflow problem: dozens of OSINT techniques, each cheap individually, that a patient human operator chains together with judgment about when to stop. The skill encodes that judgment as a prioritized playbook the agent executes against a single domain, terminating as soon as the cheapest tier produces a verified hit. The output is not just an IP but an evidence chain with a graded confidence rating, which is a notably disciplined design for a task that is usually done ad hoc.
The architecture is a five-tier escalation ladder keyed to cost, which in this context means token spend. P0 covers near-free lookups: SPF/MX/TXT record leakage, direct AAAA IPv6 records that were never placed behind the CDN, and historical DNS lookback. P1 adds subdomain enumeration, precise SSL certificate serial comparison, and Server header behavioral analysis. P2 is where the space-search engines come in — Shodan, FOFA, Censys, ZoomEye, 360 Quake, Hunter — plus favicon hashing and full-port scanning. P3 escalates to mail-header tracing, JavaScript source auditing, WHOIS-based same-organization domain correlation, GA/AdSense ID reverse lookup, and CDN-specific bypasses. P4 is the exhaustive fallback: Web Archive archaeology, cloud-provider metadata probing, WAF-evasion techniques, temporal-window attacks, and passive-intelligence aggregation. The README's tagline for P0 — hit and stop, don't waste a token — tells you the author has actually run this against real budgets.
What elevates the tool above a simple checklist is the verification pipeline. A candidate IP is never accepted raw; it passes through four checks. V-1 compares the SSL certificate serial against the CDN edge certificate, and checks whether the default certificate presented belongs to an unrelated domain — a classic multi-virtual-host origin fingerprint. V-2 inspects whether the direct-connect Server header shows nginx/apache rather than a CDN marker. V-3 performs reverse-IP binding lookup, and V-4 probes for open SSH/FTP ports, which CDN edge nodes do not expose. Each piece of evidence is graded S (decisive) through X (excluded), and the aggregate rolls into a confidence tier: certain at 95%+, highly credible at 80–95%, possible, or speculative below 60%. This evidence-grading discipline is the part most copycat tools skip, and it is what makes the output defensible in a report.
The CDN coverage table deserves attention because it moves beyond identification into vendor-specific tradecraft. Twelve-plus providers get dedicated bypass logic: Cloudflare via non-proxied ports and direct subdomains, EdgeOne via network-layer interception signatures and CVM range characteristics, Aliyun via origin-Host differences and ECS ranges, CloudFront via S3 bucket origins and ALB hostnames, Akamai via SureRoute test objects and ghost debug headers, Fastly via X-Served-By leakage, Imperva via unvalidated origin Host handling, Huawei Cloud via X-HW-Via debug headers. Critically, unknown CDNs are not dead ends: a generic fallback flow runs CDN type identification, non-standard port scanning, protocol-layer bypass, EDNS tricks, and cross-validation through the space-search engines. The author correctly notes that P0–P2 methods are inherently CDN-agnostic — the vendor-specific tricks are an accelerator, not a dependency.
The API key handling reveals the intended maturity of the audience. Keys for SHODAN_API_KEY, FOFA_EMAIL/FOFA_API_KEY, CENSYS_API_ID/CENSYS_API_SECRET, SECURITYTRAILS_KEY, ZOOMEYE_API_KEY, QUAKE_API_KEY, HUNTER_API_KEY, and VIRUSTOTAL_KEY are pasted into the top of the skill file, and the README explicitly warns not to commit the key-bearing file to a public repository, recommending .gitignore or a user-level install under ~/.claude/skills/. Alternatively, keys can be supplied conversationally for session-only memory use. Most practically: the tool works with zero keys. Everything in P0 and P1 — historical DNS, certificate comparison via crt.sh, subdomain enumeration, HTTP behavior analysis — requires no authentication, and the README claims high hit rates at that tier alone. Keys mostly buy you leverage against hardened targets at P2.
Installation is minimal by design. The recommended path is cloning the repository and launching claude from inside the directory so the skill auto-loads; alternatively, copy .claude/skills/fuck-cdn.md into an existing project's .claude/skills/ directory, or into ~/.claude/skills/ for global availability. Invocation is then either the slash command /fuck-cdn example.com or plain natural language. There is no build step, no dependency tree — the skill is a structured markdown document that instructs the agent to shell out to tools that already exist on the host: nslookup/dig/host for DNS, curl for HTTP, openssl for certificates, whois, and python3 for hashing tasks like the favicon mmh3 computation.
That cross-platform awareness is handled explicitly rather than assumed. The README ships an adaptation table mapping DNS queries to nslookup on Windows versus dig/host elsewhere, curl via Git Bash on Windows, whois replaced by web fetch where unavailable, and temp files routed to $env:TEMP versus /tmp. For a skill that orchestrates dozens of external commands, this portability layer is where most implementations quietly break, and its presence suggests the author tested on both environments.
From a defensive standpoint, this repository doubles as a useful exposure checklist. Every technique it automates is a finding you can close: SPF/MX records leaking origin ranges, AAAA records published outside the CDN, historical DNS preserved in services like ViewDNS.info and SecurityTrails, certificate transparency logs at crt.sh exposing SAN entries, backend headers like X-Real-IP/X-Backend-Server/X-Upstream-Addr passing through, default certificates on origin virtual hosts, and non-standard ports left reachable. A blue team running this skill against its own perimeter gets a prioritized remediation backlog for free — that is arguably its highest-value authorized use.
Operational caution is warranted on two fronts. First, the escalation tiers include genuinely intrusive actions: 24-port scans, /24 neighbor scanning, sensitive-path probing across 40+ locations, and WAF-evasion techniques like X-Forwarded-For spoofing. Against infrastructure you do not own, these cross from passive OSINT into active scanning that is logged and, in many jurisdictions, unlawful. The README's own disclaimer restricts use to authorized testing, security education, and CTF scenarios, and that boundary should be treated as binding. Second, because the skill instructs an LLM agent to execute arbitrary shell commands driven by web-retrieved data, standard prompt-injection hygiene applies — run it in a sandboxed environment, and treat OSINT service responses as untrusted input, the same trust boundary this publication applies to the README itself.
With 101 stars and no listed language or license, FUCK-CDN is a young, single-author project rather than a hardened community tool — the skill file is plain markdown, so auditing exactly what the agent will be instructed to do is trivial and recommended before use. Within its niche, though, it is one of the cleaner expressions of a growing pattern: packaging operator tradecraft as agent-consumable playbooks, with cost-aware escalation and evidence grading baked in. For professionals doing authorized external attack-surface mapping, or defenders stress-testing their CDN posture, it is a competent automaton of a workflow most of us have done manually more times than we care to count.
0xShe/FUCK-CDN.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.